English

A Relay a Day Keeps the AirTag Away: Practical Relay Attacks on Apple's AirTags

Cryptography and Security 2026-04-15 v2 Computers and Society

Abstract

Apple AirTags use Apple's Find My network: when nearby iDevices detect a lost tag, they anonymously forward an encrypted location report to Apple, which the tag's owner can then fetch to locate the item. That encryption protects privacy -- neither the finder nor Apple learns the owner's identity -- but it also prevents Apple from validating the correctness of received reports. We show that this design weakness can be exploited: using a relay attack, we can inject manipulated location reports so the Find My service reports a false position for a lost AirTag. The same technique can be used to deny recovery of a targeted tag (a focused DoS), since the owner is misled about its whereabouts.

Keywords

Cite

@article{arxiv.2604.10138,
  title  = {A Relay a Day Keeps the AirTag Away: Practical Relay Attacks on Apple's AirTags},
  author = {Gabriel K. Gegenhuber and Leonid Liadveikin and Florian Holzbauer and Sebastian Strobl},
  journal= {arXiv preprint arXiv:2604.10138},
  year   = {2026}
}

Comments

Poster presented at ACSAC 2025. Relay experiments were originally conducted in 2022 by Sebastian Strobl (bachelor thesis) and subsequently repeated and reproduced in 2025 by Leonid Liadveikin (university project)